See it liveHow it worksPacksQuestionnairesTrustYour recordPricingFree toolsBlogSign inStart free
All posts

Notion, Airtable, and GDPR: What Happens to Your Clients' Data

21 September 20267 min read

A bigger customer has sent you a security questionnaire, and one of the questions asks which tools you use to store their data. You've written client names, contact details, or project notes into Notion or Airtable. Now you need to explain what that means under UK GDPR. This post tells you exactly what to say.

What the law actually requires

Under Article 28 of the UK GDPR, every time you use a third-party tool to process personal data on your behalf, you need a written contract in place with that tool. Not a privacy policy you've read. A contract that binds the tool to you as a processor.

The ICO is specific about what that contract must cover: the processor can only act on your documented instructions; it must keep the data confidential; it must help you respond to data subject requests (things like access requests or deletion requests); and it must delete or return the data when you stop using the service. The contract must also address sub-processors, meaning the other companies the tool uses to run its own service.

That last point is where most small businesses get caught out. When a customer asks "who has access to our data?", the honest answer includes not just Notion or Airtable, but every company those platforms pass data to.

What Notion and Airtable actually provide

Notion

Notion publishes its GDPR position at notion.com/help/gdpr-at-notion. The data processing addendum (DPA) is incorporated by reference into your agreement the moment you use the service. There is no separate document to sign on self-serve plans. That satisfies Article 28(9), which permits a processing contract in electronic form, but it does mean you are bound by whichever version was live when you agreed, and Notion's own page notes it may be changed at any time.

For UK businesses, the important detail is that Notion's DPA incorporates the UK International Data Transfer Addendum (UK IDTA), which is the mechanism the ICO requires for restricted transfers from the UK to the US. The UK IDTA is applied on top of the EU Standard Contractual Clauses (SCCs), in line with section 119A(1) of the Data Protection Act 2018.

Data storage is the next thing to understand. As of early 2026, Notion has no EU data region. All workspace data is stored in the United States on AWS infrastructure. The SCCs and UK IDTA are the legal mechanism that makes that transfer lawful, but the data is physically in the US.

Notion maintains a sub-processor list linked from its GDPR page. The list is hosted as a live Notion page rather than a PDF, which is worth noting if a customer asks you to attach a document. You can take a dated screenshot or PDF export. To receive advance notice of sub-processor changes, you must opt in by emailing privacy@makenotion.com with the subject line "Subscribe to New Subprocessors". That notification does not happen automatically.

If your team uses Notion AI, the picture gets more complex. Notion currently uses large language models hosted by organisations including Anthropic and OpenAI. These are sub-processors. A separate AI-specific data addendum applies if Notion AI features are used and must be reviewed independently of the main DPA. For non-Enterprise plans, LLM providers retain customer data for up to 30 days before deletion. Enterprise plans get zero retention from LLM providers.

Airtable

Airtable's position is structurally similar but with one important difference in how the DPA is obtained. Airtable enters into DPAs with customers upon request, and the process routes through a DocuSign flow rather than being incorporated silently by reference. You need to actually request it.

Airtable's DPA incorporates the EU SCCs (2021/914) and the UK IDTA, covering restricted transfers from the UK to Airtable's US infrastructure. By default, Airtable servers are located in the US, hosted on AWS (US-East-1). EU data residency is available, but only on the Enterprise Scale plan, and even then only base content stays in the EU; user, auth, and metadata remain US-based.

Airtable publishes a sub-processor list of around 22 entries, including AWS, Google, OpenAI, Twilio, Salesforce, and Mailgun. Under its DPA, Airtable gives 10 business days' notice of sub-processor changes. You need to subscribe via the sub-processor page to receive those notices.

Why this matters when a customer asks

When a larger business sends you a security questionnaire or asks for your GDPR documents, they are doing their own due diligence as a controller. They need to know that the tools you use to handle their data are covered by a proper processor contract, that international transfers are legally grounded, and that they can trace the sub-processor chain.

Specifically, they will want to see:

A record of processing that lists these tools. Under Article 30 of the UK GDPR, you should maintain a record of your processing activities. Notion and Airtable need to appear in that record as processors, with the categories of data and the transfer mechanism noted.

Evidence that a DPA is in place. For Notion, this means pointing to the incorporated addendum at notion.com/help/gdpr-at-notion and capturing it. For Airtable, it means having actually requested and signed the DPA.

The transfer mechanism. Both tools rely on SCCs and the UK IDTA for UK-to-US transfers. You should be able to name this, not just say "they're compliant."

The sub-processor list. The other side may ask which sub-processors have access to their data. You need to be able to answer that, and to point to where you monitor for changes.

If you also use Notion AI or Airtable AI features, that extends the sub-processor chain to LLM providers. A customer handling sensitive data will ask about this specifically.

If any of this is missing from your supplier pack, the other side's legal or procurement team will flag it. The deal does not move until it is resolved.

What the common failure looks like

Here is the scenario that actually holds things up.

A small agency uses Notion to manage client projects. Client names, email addresses, and sometimes commercial terms are in there. A new enterprise client sends a supplier questionnaire. One question asks: "Do you use any third-party tools to process our personal data? If so, please list them and confirm a DPA is in place."

The agency answers: "We use Notion for project management. It is GDPR compliant."

That answer fails on three counts. It does not confirm a DPA is in place (because the person answering did not know one was incorporated by reference, and had never checked). It does not name the transfer mechanism. And it does not mention sub-processors.

The customer's legal team sends a follow-up. The agency spends a week finding the right page, working out what the UK IDTA is, and trying to produce a sub-processor list from memory. The contract is delayed.

The agency was not being negligent. They just had not looked at this before. The information was all there on Notion's website. The problem was not the tool; it was not having the answer ready.

A second common failure: the agency has Notion AI enabled on a Business plan. Client data passes through OpenAI as a sub-processor. The agency does not know this and does not mention it. The customer's questionnaire asks specifically about AI processing. The agency says no. That is now a material inaccuracy.

What to do about it

Here are the specific steps, in order.

1. Decide whether Notion or Airtable is actually processing personal data for you. If your workspace contains client names, contact details, project notes about individuals, or anything else that identifies a living person, the answer is yes. Act accordingly.

2. Locate and capture the DPA. For Notion: go to notion.com/help/gdpr-at-notion, find the addendum link, and save a dated PDF. For Airtable: request the DPA via the form on airtable.com/company/dpa and complete the DocuSign process.

3. Subscribe to sub-processor change notifications. For Notion, email privacy@makenotion.com with the subject "Subscribe to New Subprocessors". For Airtable, subscribe via airtable.com/company/subprocessors. Both lists are live; check them before you answer any questionnaire.

4. Check whether you have AI features enabled. If Notion AI or Airtable AI is switched on, note that LLM providers including OpenAI and Anthropic appear in the sub-processor chain. Decide whether that is appropriate for the categories of data you are processing, and document your decision.

5. Add these tools to your record of processing. Your Article 30 record should list Notion or Airtable as a processor, the categories of data in the workspace, the legal basis for the transfer (SCCs plus UK IDTA), and a reference to where the DPA lives.

6. Build a sub-processor list you can share. When a customer asks who has access to their data, you need a clear, current answer. That list should include Notion or Airtable, plus the sub-processors those platforms disclose.

Once you have those six things in order, answering a security questionnaire about your use of these tools takes minutes, not days. The information is all there. The work is in having it organised before someone asks.

If you have been sent a spreadsheet of questions and need to answer them properly, Rowpa reads your website, drafts your record of processing, checks your suppliers including Notion and Airtable, and writes the answers back into the questionnaire in the other side's own layout. You review everything before it leaves. Build your whole record free, no card needed. Pay only when you send something. rowpa.app

If what you need is a full supplier pack rather than questionnaire answers, the same applies: Rowpa turns your record into a shareable supplier pack the other side can review, with a revocable link or a PDF.

---

Sources

---

This post is for information only and does not constitute legal advice.